ESET says two Russian cybercrime groups are exploiting a high-severity WinRAR zero-day, backdooring computers that open malicious archives in phishing messages
A high-severity zero-day in the widely used WinRAR file compressor is under active exploitation by two Russian cybercrime groups.
Context & Ripple Effects
WinRAR has repeatedly been an exploitation target: researchers documented more than 100 distinct exploits of an earlier code-execution flaw in 2019, and a later WinRAR zero-day was exploited by Russia- and China-linked government-backed actors in 2023. The recurrence makes archive handling a persistent endpoint-security exposure rather than a one-off vulnerability class.
This report shifts the immediate focus to criminal operators using phishing-delivered archives. It also follows WinRAR's 2023 fix for a flaw that could enable arbitrary code execution, underscoring that attackers continue to seek leverage from a widely used file format and application.
First-order effects
- Recipients who open the malicious phishing archives risk having their computers backdoored by the two identified groups.
- Defenders must prioritize investigation of suspicious WinRAR archives and the endpoints that opened them, since exploitation is reported as active rather than merely theoretical.
Second-order effects
- Email-security and endpoint teams face pressure to improve inspection, blocking, and incident response for archive-based lures, a delivery path with a documented history of diverse exploit use in earlier WinRAR code-execution campaigns.
- Organizations that rely on WinRAR in user workflows may need to reassess how archives from external senders are handled, including whether they reach endpoints at all.
Third-order effects
- If repeated exploitation persists, archive utilities will remain high-value initial-access targets despite their mundane role in business workflows, raising the security cost of broadly distributed desktop software.
- The pattern favors layered controls around file delivery and execution over reliance on a single patch or phishing filter; the report does not establish whether this specific flaw has a fix available.
The trend: This is another data point in the durable shift toward exploiting trusted, widely installed desktop utilities as an entry point for targeted phishing operations.